gram-cli

Fail

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: HIGHCOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The wrapper script scripts/run-glam.sh determines the executable path using the GRAM_CLI_BIN environment variable. This allows for execution of arbitrary files if the environment variable is manipulated.\n- [COMMAND_EXECUTION]: The script scripts/run-glam.sh uses exec "$BIN" "$@" which passes all command-line arguments directly to the resolved binary. This can lead to argument injection if the input provided by the agent is not sanitized.\n- [CREDENTIALS_UNSAFE]: The login --print-env command explicitly prints raw authentication secrets, including Instagram session IDs and CSRF tokens, to the standard output.\n- [CREDENTIALS_UNSAFE]: The skill accesses sensitive browser data files, specifically Chrome and Firefox cookie databases, to extract authentication information.\n- [EXTERNAL_DOWNLOADS]: The skill is designed to fetch and download data from Instagram's external servers, which are untrusted sources.\n- [PROMPT_INJECTION]: The skill processes untrusted data from Instagram profiles and posts, creating a surface for indirect prompt injection. Malicious instructions embedded in Instagram content could influence the agent's behavior.\n
  • Ingestion points: profile, post, stories, and highlights commands in SKILL.md\n
  • Boundary markers: Absent\n
  • Capability inventory: Subprocess calls via scripts/run-glam.sh\n
  • Sanitization: Absent
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 26, 2026, 10:25 PM